In the Linux kernel, the following vulnerability has been resolved:
bus: fsl-mc: fix double-free on mc_dev
The blamed commit tried to simplify how the deallocations are done but,
in the process, introduced a double-free on the mc_dev variable.
In case the MC device is a DPRC, a new mc_bus is allocated and the
mc_dev variable is just a reference to one of its fields. In this
circumstance, on the error path only the mc_bus should be freed.
This commit introduces back the following checkpatch warning which is a
false-positive.
WARNING: kfree(NULL) is safe and this check is probably not required
+ if (mc_bus)
+ kfree(mc_bus);
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
19 Dec 2025, 16:44
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Linux
Debian Debian debian Linux Linux linux Kernel |
|
| CWE | CWE-415 | |
| References | () https://git.kernel.org/stable/c/12e4431e5078847791936820bd39df9e1ee26d2e - Patch | |
| References | () https://git.kernel.org/stable/c/1d5baab39e5b09a76870b345cdee7933871b881f - Patch | |
| References | () https://git.kernel.org/stable/c/3135e03a92f6b5259d0a7f25f728e9e7866ede3f - Patch | |
| References | () https://git.kernel.org/stable/c/4b23c46eb2d88924b93aca647bde9a4b9cf62cf9 - Patch | |
| References | () https://git.kernel.org/stable/c/7002b954c4a8b9965ba0f139812ee4a6f71beac8 - Patch | |
| References | () https://git.kernel.org/stable/c/873d47114fd5e5a1cad2018843671537cc71ac84 - Patch | |
| References | () https://git.kernel.org/stable/c/b2057374f326303c86d8423415ab58656eebc695 - Patch | |
| References | () https://git.kernel.org/stable/c/d694bf8a9acdbd061596f3e7549bc8cb70750a60 - Patch | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory | |
| CPE | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
03 Nov 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Jul 2025, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
10 Jul 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-10 08:15
Updated : 2025-12-19 16:44
NVD link : CVE-2025-38313
Mitre link : CVE-2025-38313
CVE.ORG link : CVE-2025-38313
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-415
Double Free
